I have the following code as input file dialog for user to upload a file:
<input #FileSelectInputDialog id="UserFile" type="file" style="display:none" (change)="onFileChange($event)" [multiple]="false" [accept]="'application/vnd.ms-excel,application/vnd.openxmlformats-officedocument.spreadsheetml.sheet'">
It's being flagged as having vulnerability by Checkmarx.
In my angular code, I read the file as follows:
reader.readAsBinaryString(target.files[0]);
The thing is, user will need to upload the file from their local drive, and I cannot limit which folder in their laptop that they have to put the file. I'm not sure also on how to "sanitize" the input filename, as target itself is an object.
Any ideas?

